Quantum Shield
Every other major chain was designed before quantum computing was a credible threat — and will have to retrofit post-quantum cryptography someday. Quantus was built for the quantum era from the genesis block: its signatures are ML-DSA, the NIST post-quantum standard (FIPS 204), immune to the algorithm that breaks ECDSA. This page explains why that matters — with every claim sourced and every number checkable.
Shor's algorithm breaks every classical signature
Bitcoin, Ethereum, and nearly every chain in production secure coins with ECDSA or Ed25519 signatures. Both rest on math problems — the elliptic-curve discrete logarithm — that Shor's algorithm solves in polynomial time on a sufficiently large quantum computer. When such a machine exists, a published public key can be turned into its private key in minutes to hours, versus 2128-class effort for classical computers. Schnorr signatures (Bitcoin Taproot) fall the same way.
✓ No such machine exists yet
NIST notes that no cryptographically relevant quantum computer has been built. Breaking ECDSA-256 needs on the order of ~1,200–1,450 logical qubits (about a million noisy physical ones, per a March 2026 Google Quantum AI estimate) — current chips run ~1,000 noisy physical qubits. The threat is real but not live today.
⚠ But exposure starts before the machine does
“Harvest now, forge later.” Any address whose public key was ever revealed on-chain — a spent address, a Taproot output, P2PK — can be archived today and forged the day the machine arrives. Blockchains are immutable, so that exposure can't be retroactively patched. The U.S. Federal Reserve (2025) flagged this as an ongoing risk for distributed ledgers, not a future one.
How we got here
ML-DSA: lattice math instead of elliptic curves
ML-DSA (Module-Lattice-Based Digital Signature Algorithm), standardized as NIST FIPS 204 on August 13, 2024, is built on the hardness of lattice problems (Module Learning With Errors and Module Short Integer Solution) — problems with no known quantum shortcut. It descends from the CRYSTALS-Dilithium submission. NIST defines three parameter sets, trading size against security category:
| Parameter set | Security category | Roughly equivalent to | Public key | Signature |
|---|---|---|---|---|
| ML-DSA-44 | Category 2 | breaking SHA-256/SHA3-256 collisions | 1,312 B | 2,420 B |
| ML-DSA-65 | Category 3 | AES-192 key search | 1,952 B | 3,309 B |
| ML-DSA-87 used by Quantus | Category 5 | AES-256 key search | 2,592 B | 4,627 B |
Categories are NIST's five post-quantum security levels from the standardization process. Values per FIPS 204; cross-checked against multiple PQC references.
Signature-size explorer
Post-quantum signatures are big — that's the honest cost of lattice security. Select a parameter set and compare it against classical signatures. An ECDSA signature is ~65 bytes; one ML-DSA-87 signature is ~4,627 bytes — about 71× larger.
Big signatures, aggregated away
A transparent Quantus transaction is ~7 KB — roughly 70× a ~100-byte Bitcoin transaction. If every transaction carried its full signature on-chain, a 12-second, 3.75 MB block would hold about 510 transactions ≈ 43 TPS. Quantus answers this with native transaction aggregation: users generate compact Plonky2 ZK proofs, and batches of proofs collapse into one succinct proof posted on-chain — packing about 5,200 transactions per block ≈ 430 TPS. Try it:
Packing figures from Quantus's architecture docs (design figures from testing: ~43 QTPS transparent, ~430 QTPS encrypted two-layer aggregation), 12-second blocks. Not measured mainnet throughput — watch the Network Dashboard for live numbers.
Are your coins quantum-exposed?
Click each address archetype to see its quantum story. The rule is simple: once a public key is on-chain, it can be harvested today and forged tomorrow — blockchains can't un-publish history.
What Quantus actually runs
From the Quantus architecture docs and upstream repos (checked Sept 29, 2026):
- Chain signatures: ML-DSA-87 — NIST security Category 5, the strongest parameter set. Post-quantum from the genesis block, so there is no migration cliff and no legacy signature history to harvest.
- Peer-to-peer encryption: ML-KEM-768 — the NIST post-quantum key-encapsulation standard (FIPS 203), via libp2p-noise, so node traffic is quantum-safe too.
- Proof of work: QPoW (Poseidon2-based) — open mining with no built-in advantage for Quantus Labs; 12-second blocks, 3.75 MB per block, 21M QTC cap.
- Aggregation: Plonky2 STARKs — transaction batches collapse into one succinct on-chain proof; this is what turns ~43 transparent TPS into ~430 aggregated TPS in testing.
- Open implementations:
qp-rusty-crystals(pure-Rust, no-std ML-DSA, NIST-ACVP test-vector verified) andquantus-cli(defaults to ML-DSA-65, ML-DSA-87 available). SS58 addresses use prefix 189 (qz…).
Audited by Neodyme, Eiger, Hashcloak, and V12 with an Immunefi competition, per September 2026 launch coverage. First exchange venue announced: NEAR Intents (no listing date confirmed as of Sept 2026).
Straight answers
Is Bitcoin broken right now?
No. No cryptographically relevant quantum computer exists, so ECDSA and Ed25519 are safe today. The risk is forward-looking: public keys already exposed on-chain are archivable now and attackable later. Coins in never-spent hashed addresses stay safe until their key is revealed by spending.
Why not just upgrade old chains later?
Upgrading signatures is the easy part; the hard part is the history. Every exposed public key ever published stays exposed forever. A chain that retrofits PQC in 2030 still has 20+ years of harvestable keys. Starting with ML-DSA at genesis means there is no pre-quantum history to exploit — that window never opened.
Does ML-DSA-65 vs 87 matter?
Both are NIST-standardized; Category 5 (ML-DSA-87) targets AES-256-equivalent effort versus AES-192 for
Category 3 (ML-DSA-65). Quantus runs ML-DSA-87 on-chain per its architecture docs — the strongest
setting — while the quantus-cli wallet tool defaults to ML-DSA-65 with 87 available.
Are there downsides to post-quantum signatures?
Honestly, yes: size (a 4.6 KB signature vs 65 bytes) and somewhat slower verification. Quantus's answer is native aggregation — the per-transaction on-chain footprint shrinks as batches grow. The tradeoff is deliberate: pay bytes now, never face a migration cliff later.
Could quantum computers break ML-DSA too?
No known quantum algorithm breaks the lattice problems ML-DSA rests on — that's the entire basis of the NIST standard. Cryptography is never "proven" safe, but ML-DSA survived the most scrutinized selection process in the field's history and is the U.S. federal standard.
Where do I read the real specs?
Start with FIPS 204 itself, Quantus's architecture docs, the qp-rusty-crystals implementation, and the quantus-cli README.
Sources
- FIPS 204 — Module-Lattice-Based Digital Signature Standard, published Aug 13, 2024: csrc.nist.gov/pubs/fips/204/final
- ML-DSA parameter sizes (pk/sig bytes per set): tq42-pqc-oss ML-DSA reference
- Quantus architecture docs — ML-DSA-87 signatures, ML-KEM-768 P2P, 3.75 MB blocks, QTPS design table: Quantus-Network/docs · architecture.md
- qp-rusty-crystals — pure-Rust ML-DSA, NIST-ACVP KAT-verified: Quantus-Network/qp-rusty-crystals
- quantus-cli — Dilithium/ML-DSA support, default ML-DSA-65: Quantus-Network/quantus-cli
- Quantum timeline estimates — Google Quantum AI resource estimate (Mar 2026), Citi Institute window 2027–2030, National Academies 2030s: via Sept 2026 launch coverage, e.g. The Bit Times
- Federal Reserve (2025) on harvest-now/decrypt-later risk for distributed ledgers; NIST: no cryptographically relevant quantum computer has been built.
Every figure on this page was re-verified against these sources on Sept 29, 2026. If a source moves, the claim moves with it — nothing here is asserted on vibes.